← Back

Clippercms

clippercms

Vendor: Clippercms • 10 CVEs

CVEs (10)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Clippercms
1Clippercms
May 15, 2025
Oct 13, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
ClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the pkg_url parameter at /manager/index.php.
1Clippercms
1Clippercms
May 15, 2025
Oct 13, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
ClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the rss_url_news parameter at /manager/index.php.
1Clippercms
1Clippercms
Nov 21, 2024
Aug 15, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
CMS Clipper 1.3.3 has XSS in the Security tab search, User Groups, Resource Groups, and User/Resource Group Links fields.
1Clippercms
1Clippercms
Nov 21, 2024
Nov 21, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
ClipperCMS 1.3.3 allows remote authenticated administrators to upload .htaccess files.
1Clippercms
1Clippercms
Nov 21, 2024
Nov 11, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
ClipperCMS 1.3.3 does not have CSRF protection on its kcfinder file upload (enabled by default). This can be used by an attacker to perform actions for an admin (or any user with the file upload capability). With this vu...Show more
ClipperCMS 1.3.3 does not have CSRF protection on its kcfinder file upload (enabled by default). This can be used by an attacker to perform actions for an admin (or any user with the file upload capability). With this vulnerability, one can automatically upload files (by default, it allows html, pdf, xml, zip, and many other file types). A file can be accessed publicly under the "/assets/files" directory.Show less
1Clippercms
1Clippercms
Nov 21, 2024
Jul 12, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
ClipperCMS 1.3.3 has stored XSS via the Full Name field of (1) Security -> Manager Users or (2) Security -> Web Users.
1Clippercms
1Clippercms
Nov 21, 2024
Jul 3, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
ClipperCMS 1.3.3 has stored XSS via the "Tools -> Configuration" screen of the manager/ URI.
1Clippercms
1Clippercms
Nov 21, 2024
May 31, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
ClipperCMS 1.3.3 has XSS in the "Module name" field in a "Modules -> Manage modules -> edit" action to the manager/ URI.
1Clippercms
1Clippercms
Nov 21, 2024
May 31, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
ClipperCMS 1.3.3 allows Session Fixation.
1Clippercms
1Clippercms
Nov 21, 2024
May 24, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Stored cross-site scripting (XSS) vulnerability in the "Site Name" field found in the "site" tab under configurations in ClipperCMS 1.3.3 allows remote attackers to inject arbitrary web script or HTML via a crafted site...Show more
Stored cross-site scripting (XSS) vulnerability in the "Site Name" field found in the "site" tab under configurations in ClipperCMS 1.3.3 allows remote attackers to inject arbitrary web script or HTML via a crafted site name to the manager/processors/save_settings.processor.php file.Show less